Repository navigation
Expand file tree
/
Copy pathclippy.toml
More file actions
30 lines (29 loc) · 1.9 KB
/
Copy pathclippy.toml
File metadata and controls
30 lines (29 loc) · 1.9 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
# Workspace-wide Clippy configuration for the Maestro crates.
#
# NOTE: clippy uses the NEAREST clippy.toml (no merging), so if a crate ever
# grows its own clippy.toml it must duplicate these settings.
# Ban raw canonicalize: on Windows, std canonicalize returns verbatim
# `\\?\C:\...` paths that break external tools (git rejects them as clone
# destinations), leak into model prompt context, and poison path-equality
# keys (sandbox containment zones, workspace roots, session paths). Use
# `dunce::canonicalize` (identical to std on Unix/macOS; strips the verbatim
# prefix on Windows when safely representable).
#
# Caveat: dunce keeps the verbatim form for paths it cannot safely simplify
# (notably > 260 chars or reserved device names), so prefix checks between
# two independently canonicalized paths can mismatch on Windows for very
# long paths (containment checks then fail closed).
#
# Enforcement boundary: `tokio::fs::canonicalize` remains allowed — there is
# no async dunce equivalent, and the handful of async call sites need an
# explicit spawn_blocking design rather than a mechanical swap.
disallowed-methods = [
{ path = "std::fs::canonicalize", reason = "returns \\\\?\\ verbatim paths on Windows; use dunce::canonicalize" },
{ path = "std::path::Path::canonicalize", reason = "returns \\\\?\\ verbatim paths on Windows; use dunce::canonicalize" },
# Raw hosted-runner journal writes have repeatedly wedged the runtime when
# their errors were propagated from event paths (dead event pump, drains
# permanently rejected as "already draining"). Callers must pick the
# wrapper that states their failure semantics; see the doc comment on
# SharedRunner::persist_thread.
{ path = "maestro_tui::hosted_runner::SharedRunner::persist_thread", reason = "use persist_thread_or_defer / persist_thread_for_request / persist_thread_best_effort; raw journal-write errors wedge the runtime" },
]